PT-2026-96833 · Nuclei · Nuclei
CVE-2026-76802
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
4.7
Medium
| Vector | AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Nuclei versions 3.0.0 through 3.9.9
Description
The DAST template loading branch fails to apply the unsigned code-template signature check before accepting a template that contains both a
fuzzing: block and an unsigned code: block. When the -dast flag is enabled, an untrusted multiprotocol template can place an unsigned code request into the execution queue, allowing the execution of arbitrary shell commands. This bypasses the cryptographic signature requirement and the -code flag normally required for code: protocol templates. The issue affects CLI DAST scans and SDK integrations that enable DAST while accepting attacker-supplied templates.Recommendations
Update Nuclei to version 3.10.0.
Avoid running DAST scans with untrusted templates.
Do not use the
-dast flag with templates from unverified sources.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nuclei